Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,465Referência 23,022GitHub PoC 15,031VulnCheck XDB 8,860Nuclei 4,361Metasploit 3,491✓ verified onlyrecentpopularrisk
5,629 exploits
Referência✓ VexDay Proof
Evince Document Viewer - 'DocumentMedia' Remote Buffer Overflow
Stack-based buffer overflow in the ps_gettext function in ps.c for GNU gv 3.6.2, and possibly earlier versions, allows u
28RISK
open ↗Referência✓ VexDay Proof
PHPManta 1.0.2 - 'view-sourcecode.php' Local File Inclusion
Directory traversal vulnerability in Mdoc/view-sourcecode.php for phpManta 1.0.2 and earlier allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
NuRems 1.0 - 'propertysdetails.asp' SQL Injection
SQL injection vulnerability in propertysdetails.asp in Dynamic Dataworx NuRealestate (NuRems) 1.0 and earlier allows rem
23RISK
open ↗Referência✓ VexDay Proof
BrewBlogger 1.3.1 - 'printLog.php' SQL Injection
SQL injection vulnerability in printLog.php in BrewBlogger (BB) 1.3.1 allows remote attackers to execute arbitrary SQL c
23RISK
open ↗Referência✓ VexDay Proof
AspPired2Poll 1.0 - 'MoreInfo.asp' SQL Injection
SQL injection vulnerability in MoreInfo.asp in The Net Guys ASPired2Poll 1.0 and earlier allows remote attackers to exec
23RISK
open ↗Referência✓ VexDay Proof
StoryStream 4.0 - 'baseDir' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in iWonder Designs Storystream 0.4.0.0 allow remote attackers to exec
23RISK
open ↗Referência✓ VexDay Proof
blogme 3.0 - Cross-Site Scripting / Authentication Bypass
Multiple cross-site scripting (XSS) vulnerabilities in comments.asp in BlogMe 3.0 allow remote attackers to inject arbit
23RISK
open ↗Referência✓ VexDay Proof
XMPlay 3.3.0.4 - '.M3U' Filename Local Buffer Overflow
Stack-based buffer overflow in Un4seen XMPlay 3.3.0.5 and earlier allows remote attackers to execute arbitrary code via
50RISK
open ↗Referência✓ VexDay Proof
Powies pForum 1.29a - 'editpoll.php' SQL Injection
SQL injection vulnerability in editpoll.php in Powie's PHP Forum (pForum) 1.29a and earlier allows remote attackers to e
23RISK
open ↗Referência✓ VexDay Proof
e-Ark 1.0 - '/src/ark_inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in src/ark_inc.php in e-Ark 1.0 allows remote attackers to execute arbitrary PHP
23RISK
open ↗Referência✓ VexDay Proof
SimpleBlog 2.3 - '/admin/edit.asp' SQL Injection
SQL injection vulnerability in admin/edit.asp in 8pixel.net simpleblog 2.3 and earlier allows remote attackers to execut
23RISK
open ↗Referência✓ VexDay Proof
Mambo Component com_flyspray < 1.0.1 - Remote File Disclosure
Directory traversal vulnerability in startdown.php in the Flyspray ME 1.0.1 (com_flyspray) component for Mambo allows re
23RISK
open ↗Referência✓ VexDay Proof
PHP-Nuke NukeAI Module 3b - 'util.php' Remote File Inclusion
PHP remote file inclusion vulnerability in modules/NukeAI/util.php in the NukeAI 0.0.3 Beta module for PHP-Nuke, aka Pro
23RISK
open ↗Referência✓ VexDay Proof
Songbird Media Player 0.2 - Format String Denial of Service (PoC)
Format string vulnerability in Songbird Media Player 0.2 and earlier allows remote attackers to cause a denial of servic
23RISK
open ↗Referência✓ VexDay Proof
VUPlayer 2.44 - '.m3u' UNC Name Buffer Overflow (Metasploit)
Stack-based buffer overflow in VUPlayer 2.44 and earlier allows remote attackers to execute arbitrary code via a long st
50RISK
open ↗Referência✓ VexDay Proof
AtomixMP3 < 2.3 - '.m3u' Local Buffer Overflow
Stack-based buffer overflow in AtomixMP3 2.3 and earlier allows remote attackers to execute arbitrary code via a long pa
28RISK
open ↗Referência✓ VexDay Proof
F-Prot AntiVirus 4.6.6 - 'ACE' Denial of Service
FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to cause a denial of service (infinit
23RISK
open ↗Referência✓ VexDay Proof
awrate.com Message Board 1.0 - 'search.php' Remote File Inclusion
PHP remote file inclusion vulnerability in login.php.inc in awrate 1.0 allows remote attackers to execute arbitrary PHP
23RISK
open ↗Referência✓ VexDay Proof
Ultimate HelpDesk - Cross-Site Scripting / Local File Disclosure
Cross-site scripting (XSS) vulnerability in index.asp in Ultimate HelpDesk allows remote attackers to inject arbitrary w
23RISK
open ↗Referência✓ VexDay Proof
BlazeVideo HDTV Player 2.1 - '.PLF' Local Buffer Overflow
Stack-based buffer overflow in BlazeVideo HDTV Player 2.1, and possibly earlier, allows remote attackers to execute arbi
23RISK
open ↗Referência✓ VexDay Proof
VMware 5.5.1 - 'ActiveX' Local Buffer Overflow
Buffer overflow in an ActiveX control in VMWare 5.5.1 allows local users to execute arbitrary code via a long VmdbDb par
23RISK
open ↗Referência✓ VexDay Proof
J-OWAMP Web Interface 2.1b - 'link' Remote File Inclusion
PHP remote file inclusion vulnerability in JOWAMP_ShowPage.php in J-OWAMP Web Interface 2.1 allows remote authenticated
23RISK
open ↗Referência✓ VexDay Proof
D-Link DWL-2000AP 2.11 - ARP Flood Remote Denial of Service
D-LINK DWL-2000AP+ firmware 2.11 allows remote attackers to cause (1) a denial of service (device reset) via a flood of
23RISK
open ↗Referência✓ VexDay Proof
Fantastic News 2.1.4 - 'news.php' SQL Injection
SQL injection vulnerability in news.php in Fantastic News 2.1.4 and earlier allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
SpotLight CRM 1.0 - 'login.asp' SQL Injection
Multiple SQL injection vulnerabilities in login.asp in AppIntellect SpotLight CRM 1.0 allow remote attackers to execute
23RISK
open ↗Referência✓ VexDay Proof
mxBB Module ErrorDocs 1.0 - 'common.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/common.php in the ErrorDocs 1.0.0 and earlier module for mxBB (mx_er
23RISK
open ↗Referência✓ VexDay Proof
CuteNews aj-fork 167f - 'cutepath' Remote File Inclusion
PHP remote file inclusion vulnerability in inc/shows.inc.php in cutenews aj-fork (CN:AJ) 167f and earlier allows remote
23RISK
open ↗Referência✓ VexDay Proof
Phorum 3.2.11 - 'common.php' Remote File Inclusion
PHP remote file inclusion vulnerability in common.php in Phorum 3.2.11 and earlier allows remote attackers to execute ar
23RISK
open ↗Referência✓ VexDay Proof
Tucows Client Code Suite (CSS) 1.2.1015 - Remote File Inclusion
PHP remote file inclusion vulnerability in libs/tucows/api/cartridges/crt_TUCOWS_domains/lib/domainutils.inc.php in Tuco
23RISK
open ↗Referência✓ VexDay Proof
mxBB Module newssuite 1.03 - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/newssuite_constants.php in the NewsSuite 1.03 module for mxBB allows
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.